GithubHelp home page GithubHelp logo

About me ๐Ÿ‘จโ€๐Ÿ’ป

  • ๐Ÿ˜„ Pronouns: He/Him
  • ๐Ÿ‡ง๐Ÿ‡ท I am Brazilian! Currently Living in Sรฃo Paulo
  • ๐ŸŽ“ Graduated in Computer Engineering in University of Campinas (UNICAMP), with an exchange program to Russia ๐ŸŽ’
  • ๐Ÿ’ป My favorite language is Kotlin, and I love to code using VIM
  • ๐Ÿ•ถ๏ธ Fun facts:
    • ๐Ÿˆ I'm a very proud cat dad! His name is Ravi ๐Ÿฅฐ
    • ๐ŸŽฎ I'm a fan of Dark Souls series and I'm enjoying my recently bought Playstation 5 ๐Ÿ˜‹
    • ๐Ÿท I love wine and I'm starting to learn about them hehe
  • ๐Ÿข I work at Google on Google Open Source Security Team (GOSST)
  • ๐Ÿ“– My next learning objectives are French and improving general communication/leading skills
  • ๐Ÿ’ฌ I'd be more than happy to receive any contact through [email protected], Twitter or LinkedIn ๐Ÿ˜ƒ

About GOSST ๐Ÿ‘ป

Logo of GOSST team

GOSST was created as a response to the current scenario of increasing attacks on supply chain projects. The team counts with experienced open-source contributors and works alongside the Open Source Security Foundation (OpenSSF) to develop and spread solutions to make open software safer at scale. You can read more about Google initiatives on open source on this blogpost.

More specifically, I'm part of a sub-team responsible for our direct engagement with the Open Source community. We work with critical open source projects to help them increase their security, in any way we can. As a team, our goal is to:

  • Build individual analyses and approaches for each project.
  • Evaluate and suggest solutions or enhancements that would better fit the repository and not burden the maintainers.
  • Welcome and conduct discussions about our suggestion or any security solutions the maintainers prefer, as we can surely provide specific help according to their demands.
  • If possible and wanted, implement the changes ourselves via PRs to contribute with the discussed improvements.
  • Collect all kinds of feedback, as we work closely with OpenSSF and any complaints would be kindly heard.

Please read more about our acchievements on our 1-year blogpost.

Security Solutions

See below some of the tools developed by GOSST and the OpenSSF:

  • Scorecard: automated checks to evaluate a project's security practices and suggest improvements as needed
  • SLSA (pronounced "salsa"): a standard and protocol to ensure an artifact's provenance, guaranteeing it comes from the expected location and process. It prevents tampering and improves the integrity of infrastructure and consumed packages
  • Sigstore: keyless signing and verification of artifacts
  • OSS-FUZZ: automated fuzzing at scale, now fuzzing 800+ projects in 6 languages
  • OSV: a precise human - and machine - readable database of vulnerabilities that maps affected software versions across open source ecosystems
  • OSV-Scanner: A frontend for the OSV Database that connects a projectโ€™s list of dependencies with the vulnerabilities that affect them
  • GUAC: graph database of security metadata (in development)

Diogo Teles Sant'Anna's Projects

angular icon angular

The modern web developerโ€™s platform

arrow icon arrow

Apache Arrow is a multi-language toolbox for accelerated data interchange and in-memory processing

bootstrap icon bootstrap

The most popular HTML, CSS, and JavaScript framework for developing responsive, mobile first projects on the web.

cryptography icon cryptography

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers.

curl icon curl

A command line tool and library for transferring data with URL syntax, supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, POP3, POP3S, RTMP, RTMPS, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. libcurl offers a myriad of powerful features

d3 icon d3

Bring data to life with SVG, Canvas and HTML. :bar_chart::chart_with_upwards_trend::tada:

dbus icon dbus

Native Go bindings for D-Bus

hackathon-covid19 icon hackathon-covid19

Code of solution used for a hackathon organized by Patronos, themed as solutions for covid-19 effects

hdf5 icon hdf5

Official HDF5ยฎ Library Repository

idna icon idna

Internationalized Domain Names for Python (IDNA 2008 and UTS #46)

jsonrpc2 icon jsonrpc2

Package jsonrpc2 provides a client and server implementation of JSON-RPC 2.0 (http://www.jsonrpc.org/specification)

libraw icon libraw

LibRaw is a library for reading RAW files from digital cameras

little-cms icon little-cms

A free, open source, CMM engine. It provides fast transforms between ICC profiles.

llvm-project icon llvm-project

The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.

magic_enum icon magic_enum

Static reflection for enums (to string, from string, iteration) for modern C++, work with any enum type without any macro or boilerplate code

mariadb-server icon mariadb-server

MariaDB server is a community developed fork of MySQL server. Started by core members of the original MySQL team, MariaDB actively works with outside developers to deliver the most featureful, stable, and sanely licensed open SQL server in the industry.

mc504 icon mc504

Projetos da disciplina MC504, UNICAMP, 2018-1

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.